Architecture Interview Questions — All Categories
98 questions across 27 categories
Designing systems under real constraints: requirements, trade-offs, and the reasoning behind a specific design choice.
A customer's procurement team now requires an SBOM for every release. How would you design SBOM generation into your build pipeline so it's actually useful, not just a compliance checkbox?
AdvancedDevSecOps8 min
How would you design volume mounts for a containerized production database, considering both data persistence and backup requirements?
AdvancedDocker7 min
How would you harden a container to run with a read-only root filesystem, given that some part of the application still needs to write to disk somewhere?
AdvancedDocker7 min
Two containers need to share the same data — one writes, another reads. How would you design this safely with Docker volumes?
IntermediateDocker6 min
Standard Docker volumes are tied to a single host — how would you give containers access to network-backed storage that survives even the host itself being replaced?
AdvancedDocker7 min
How would you decide between Cloud Functions, Cloud Run, and GKE for a new workload, beyond just 'serverless is simpler'?
IntermediateGCPCloud FunctionsCloud Run7 min
How would you design least-privilege IAM for a Cloud Function that reads from Pub/Sub and writes to a specific Cloud Storage bucket?
IntermediateGCP6 min
How would you design a CI/CD pipeline's GCP authentication using service account impersonation instead of a downloaded key, and why is that safer?
AdvancedGCP7 min
How would you design a fast, event-driven alerting system to catch an accidentally-public Cloud Storage bucket within minutes, GCP-native?
ExpertGCPCloud Storage8 min
How would you design Cloud Storage lifecycle rules to automatically reduce cost as objects age, without risking premature deletion of data still in use?
IntermediateGCPCloud Storage7 min
A repository has grown to several gigabytes because it stores large binary assets (design files, ML model weights) directly, making every clone painfully slow. How would you fix this?
IntermediateGit7 min
Design a migration from long-lived AWS access keys stored as GitHub Actions secrets to OIDC-based short-lived credentials, for an organization with 40 repositories deploying to production.
AdvancedGitHub ActionsAWSOIDC12 min
How would the OIDC-based deploy design change for a monorepo where multiple independent deploy targets live in one repository?
ExpertGitHub ActionsAWS8 min
How would you design a GitHub Actions deployment workflow so that deploying to production requires a manual approval, while deploying to staging doesn't?
IntermediateGitHub Actions6 min
A team wants to auto-merge every Dependabot PR that passes CI, to reduce the toil of manually reviewing hundreds of dependency bumps. What's the actual risk, and how would you design this safely?
AdvancedGitHubDevSecOps8 min
You have a monorepo where a single commit might touch 1 service or 15. How would you use GitLab's dynamic child pipelines so you only run CI for the services that actually changed?
AdvancedGitLab CI/CD8 min
A shared library lives in its own GitLab project, consumed by 5 downstream application projects. How would you trigger those downstream pipelines automatically when the library changes?
IntermediateGitLab CI/CD6 min
Reviewers keep approving frontend PRs based on reading the diff alone, and subtle visual bugs keep slipping through to production. How would GitLab Review Apps address this?
IntermediateGitLab CI/CD6 min
In a GitOps setup, how do you actually promote a change from staging to production — is it a separate deploy, or literally the same Git commit moving between environments?
IntermediateGitOps7 min
GitOps means Git is the source of truth for everything deployed, but you obviously can't commit plaintext secrets to Git. How do you actually reconcile this?
AdvancedGitOpsSecurity8 min
How would you share common templates (labels, resource boilerplate) across many microservice charts without copy-pasting them into every chart?
AdvancedHelm7 min
How would you design a deploy pipeline so a killed CI job can never leave a Helm release ambiguously stuck?
ExpertHelmKubernetes8 min
How would you set up and manage a private Helm chart repository for an organization's internal charts?
IntermediateHelm6 min
How would you design scheduled Terraform drift detection so it alerts the right team without becoming noise nobody reads?
AdvancedTerraform8 min